Automated Security Rule-Set Verification for Network Traffic Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security rule-sets in complex network architectures is challenging, particularly in verifying and amending policies to accommodate connectivity requests while considering potential side effects and optimizing traffic flow.

Innovation Solution

An automated method and system that recognize all possible combinations of values in a connectivity request, verify them against initial and amended rule-sets, calculate relative amounts of satisfied and dissatisfied traffic, and classify the requests based on predefined thresholds to generate optimized rule-sets that allow extra traffic while minimizing dissatisfied traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of security rule-sets is performed in complex network architectures, then security policies can be implemented, but the complexity of verifying and amending policies increases significantly

Engineering Contradiction:
Improvesecurity policy verificationVSAvoidrule-set management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-verification of security rule-sets by automatically analyzing connectivity requests against the rule-set and identifying potential issues without requiring manual verification, thereby reducing management complexity while maintaining reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides feedback mechanisms that automatically report verification results, conflicts, and amendments needed in the security rule-sets, enabling continuous improvement and reduction of management complexity through automated information loops

Inventive Principle:
Principle #23Feedback

2Productivity

If security rule-sets are amended to accommodate connectivity requests, then traffic flow is optimized, but side effects and dissatisfied traffic may increase

Engineering Contradiction:
Improvetraffic flow optimizationVSAvoiddissatisfied traffic
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of connectivity requests against the security rule-set before implementing amendments, predicting potential side effects and dissatisfied traffic, thereby allowing proactive adjustment to minimize harmful effects while optimizing traffic flow

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system identifies potential dissatisfied traffic and side effects in advance and implements countermeasures by adjusting the rule-set amendments to prevent or minimize these harmful effects before they occur

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If automated verification of connectivity requests is performed against security rule-sets, then management efficiency is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidverification processing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The verification process is segmented into distinct phases including connectivity request analysis, rule-set evaluation, conflict identification, and amendment generation, allowing parallel processing and optimization of each segment to reduce overall processing time while maintaining high management efficiency

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9122990B2Method and system for management of security rule set
Publication Date: 2015.09.01 TUFIN SOFTWARE TECH
  • US9122990B2 patent drawing
  • US9122990B2 patent drawing
  • US9122990B2 patent drawing

AI summary

There are provided a method of automated managing one or more security rule-sets and a system thereof. The method comprising: obtaining data characterizing a connectivity request and an amended rule-set, the amended rule-set being derivative of an initial rule-set amended to fit the connectivity request; automated verifying each possible combination of values in the connectivity request against the initial rule-set and the amended rule-set; calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied requested traffic; automated comparing the calculated values and/or derivatives thereof with a predefined threshold; and automated classifying the amended rule-set as applicable for implementation if the results of the automated comparing match a predefined verification criterion.